No Easy Win: Using Splunk Enterprise Security to Disrupt Modern Attackers

September 07, 2026

Attackers don’t need to find every weakness in an organization. They only need to find the gaps defenders overlook.

 

At Splunk .conf26, Brandon Terrell, Principal Engineer at Optiv + ClearShark, will explore how federal security teams can use Splunk Enterprise Security (ES) to make those gaps harder to exploit and make every step of an attack more difficult.

 

In his session, “No Easy Win: Using Splunk Enterprise Security to Disrupt Modern Attackers,” Terrell will take a practical look at how adversaries operate, what they are trying to accomplish, and how defenders can apply fundamental security controls and threat-informed defense to disrupt the attack chain.

 

 

Think Like an Attacker. Defend with Purpose

Modern attackers have a wide range of techniques at their disposal, but their objectives and behaviors often follow recognizable patterns. The presentation starts by examining the attack lifecycle and the importance of adding friction at each stage. As Terrell’s presentation emphasizes, attackers frequently exploit the security fundamentals organizations skip.

 

That makes understanding attacker behavior essential.

 

Terrell will introduce threat-informed defense as a way to align security efforts with the adversaries, capabilities, and tactics most relevant to an organization.

 

 

From Threat Intelligence to Detection

Knowing how attackers operate is only part of the challenge. Security teams also need to understand which threats are most relevant to their environment and whether their current defenses can detect them.

 

The session explores the role of cyber threat intelligence, from internal programs and industry reporting to resources such as Splunk SURGe and other threat research, to help organizations better understand their threat landscape.

 

From there, the focus shifts to identifying defensive gaps.

 

Terrell will walk through areas including detection coverage, data sources, logging quality, network visibility, security tooling, agent coverage, and detection quality. The goal is not simply to have more detections, but to understand which detections provide meaningful coverage against the techniques that matter most.

 

 

Putting Splunk Enterprise Security to Work

This is where Splunk Enterprise Security becomes a critical part of the strategy.

 

The presentation highlights how MITRE ATT&CK provides the framework and vocabulary for understanding adversary behavior, while Splunk Enterprise Security helps operationalize that knowledge through mapped detection content and security analytics.

 

The result is a more deliberate approach to detection: understand the threats, identify the gaps, prioritize the techniques that matter, and use the tools and content available to strengthen defenses.

 

 

No Easy Wins for Attackers

The takeaway is straightforward: security teams don’t have to stop every attack at the first step to make a difference. By understanding how adversaries operate and systematically adding friction throughout the attack chain, defenders can make attacks more difficult and visible.

Follow Optiv + ClearShark
LinkedIn: www.linkedin.com/company/clearshark
YouTube: www.youtube.com/c/OptivInc

Brandon Norris
Brandon Norris is a seasoned marketing leader, brand builder, and content creator currently serving as Senior Manager of Strategic Marketing at Optiv + ClearShark. In this role, he drives visibility, engagement, and growth across federal cybersecurity and technology solutions, helping to communicate the value of cutting-edge cybersecurity services to government audiences. Prior to joining Optiv + ClearShark, Brandon held leadership roles in technology marketing — including at KTL Solutions, where he led strategic initiatives for a major Microsoft partner. Known for his growth-oriented mindset and passion for impactful storytelling, Brandon combines creativity with data-driven strategy to elevate brands and strengthen audience connections.

About Optiv + ClearSharkTM

Optiv + ClearShark is a cybersecurity and IT solutions provider focused exclusively on serving the U.S. federal government. From the data center, cloud and to the edge, we have decades of experience securing and modernizing federal agency data and infrastructure. Our world-class advisory and engineering team is comprised of mission-focused, results-driven subject-matter experts with deep technology and agency domain knowledge and security clearances.

 

Part of Optiv, the cyber advisory and solutions leader, Optiv + ClearShark partners with federal agencies to advise, deploy and operate complete cybersecurity programs.